LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Western Alliance Bank ("WAB") Data Breach Notice (Oregon Attorney General)

MEDIUM severityConfirmedHow we verify

Western Alliance Bank ("WAB") Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 30, 2025
Western Alliance Bank ("WAB") Data Breach Notice (Oregon Attorney General)

Occurred October 12, 2024 · publicly disclosed June 30, 2025. Approximately 78338 people affected.

MEDIUM
Severity
78338
People affected
1
Data types exposed
June 30, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Western Alliance Bank disclosed a data breach on June 30, 2025, that exposed the personal information of 78,338 individuals. The breach occurred on October 12, 2024; anyone who may have been affected should review the notice from the Oregon Attorney General and follow the steps provided.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
78338 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Financial institutions remain frequent targets in a threat landscape where attackers seek concentrated stores of identity and account data. Against that backdrop, a formal notice from Western Alliance Bank ("WAB") has entered the public record through a state regulator, confirming that personal information was involved in an incident first dated months earlier.

According to a filing reported to the Oregon Department of Justice on June 30, 2025, Western Alliance Bank notified Oregon residents of a data breach. The filing places the incident itself on October 12, 2024, and states that 78,338 people were affected. Exact technical details beyond that notice remain limited in the public disclosure.

What happened

Western Alliance Bank ("WAB") submitted a data breach notice that was reported to the Oregon Attorney General’s office, via the Oregon Department of Justice, on June 30, 2025. The notice concerns Oregon residents and identifies the underlying incident date as October 12, 2024. The filing indicates that 78,338 individuals were affected and that the exposed material is described as personal information, as characterized in the breach notification itself.

Public detail in the available record does not describe how the incident was discovered, what systems were involved, whether data left the bank’s environment in a confirmed exfiltration, or whether a specific intrusion method was identified. No threat actor is named in the facts provided. The gap between the October 12, 2024 incident date and the June 30, 2025 reporting date is part of the official timeline; reasons for that interval are not explained in the disclosure summarized here.

How a breach like this happens

Incidents affecting banks and similar financial firms typically begin with one of several common entry paths: stolen or phished employee credentials, exploitation of a vulnerable remote-access or web-facing system, malware delivered through email, or misuse of legitimate access by an insider or compromised vendor. Once inside a network, attackers often move laterally, seeking file shares, customer databases, backup stores, or identity systems that hold concentrated personal records.

In many cases the first clear signal is unusual outbound traffic, ransomware notes, or alerts from monitoring tools rather than an immediate public announcement. Organizations then investigate scope, contain affected systems, and determine which individuals and data elements require notification under state law. None of these general patterns should be read as a confirmed description of the Western Alliance Bank event; they are background on how breaches of this broad type often unfold when method and actor are not publicly attributed.

Who is Western Alliance Bank ("WAB")?

Western Alliance Bank is a United States banking organization. Banks in this category hold customer identity records, account relationships, and related financial and contact data needed to open accounts, process transactions, extend credit, and meet regulatory obligations. They operate under federal and state oversight and routinely handle Social Security numbers, addresses, account numbers, and similar identifiers as part of ordinary business.

A breach affecting a bank is consequential because the same data that enables legitimate banking can also be reused for identity theft, account takeover attempts, or targeted fraud. Even when only a subset of customers in one state is named in a particular filing, the underlying systems may serve a wider population, which is why notices of this kind draw attention beyond the listed residents.

The information in question

The breach notification, as reflected in the Oregon filing summary, names the exposed material as personal information. It does not, in the facts available here, itemize every field—such as whether full Social Security numbers, driver’s license data, account numbers, or other specific elements were included.

Organizations of this kind typically maintain names, addresses, dates of birth, government identifiers, account and routing details, and contact information. Those categories are standard for the sector; they are not confirmed as the exact contents of this incident beyond the notice’s reference to personal information. Where the public record stops at that phrase, the precise data elements remain unconfirmed outside the formal notification language.

The real-world impact

For affected people, the primary risks are secondary misuse of identity data: fraudulent credit applications, attempts to open accounts in someone else’s name, social-engineering calls that reference real personal details, or phishing that appears more credible because it draws on leaked information. Harm is not automatic; much depends on what exactly was exposed, whether it is combined with other breaches, and how quickly individuals monitor credit and account activity.

For the bank, consequences can include notification and remediation costs, regulatory scrutiny, customer support load, and reputational pressure. The filing’s count of 78,338 affected people establishes scale for this notice; it does not by itself prove financial loss to any individual or quantify organizational damage. Public detail does not assign fault or describe security controls in place at the time.

What to do if you're exposed

If you believe you may be among those notified, treat the situation as a prompt for steady hygiene rather than panic. Review any official letter from the bank for the exact data categories it lists and for any credit-monitoring or identity-protection offer included. Place a fraud alert or credit freeze with the major credit bureaus if appropriate for your situation, and monitor bank, credit-card, and credit-report activity for unfamiliar inquiries or accounts. Be cautious of unsolicited calls or messages that claim to be from the bank and ask for passwords, one-time codes, or remote access.

Change passwords on important accounts if you reuse credentials, enable multi-factor authentication where available, and keep tax and financial documents secure. You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets, which can help you prioritize further password and account reviews. If you receive a notice naming you, keep a copy and follow the bank’s stated instructions for any dedicated support channel it provides.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyWestern Alliance Bank ("WAB") security record
74/100
DoxxScan™ · Moderate doxx risk
B 80Good record

1 reported incident on record.

See Western Alliance Bank ("WAB")’s full breach history →

More recent breaches

Decisely Insurance Services Data Breach Notice (Oregon Attorney General)December 30, 2025Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)December 29, 2025Apro, LLC d/ Data Breach Notice (Oregon Attorney General)December 29, 2025CareOregon Data Breach Notice (Oregon Attorney General)December 26, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Western Alliance Bank ("WAB") Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram